MediaWiki Zero-Day Vulnerability Affects CommentFormatter/CommentParser.php
CVE-2024-34507
7.4HIGH
What is CVE-2024-34507?
A Cross-Site Scripting (XSS) vulnerability exists in MediaWiki due to improper handling of the 0x1b character in includes/CommentFormatter/CommentParser.php. This issue affects various versions of MediaWiki, allowing attackers to inject malicious scripts through specially crafted inputs, such as those seen in Special:RecentChanges. Users of vulnerable versions may face increased risk of data theft and other malicious exploits.
